CVE-2025-30650 Details
Description
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS: * all versions before 22.4R3-S8, * from 23.2 before 23.2R2-S6, * from 23.4 before 23.4R2-S6, * from 24.2 before 24.2R2-S3, * from 24.4 before 24.4R2, * from 25.2 before 25.2R2.
A vulnerability allowing missing authentication for critical functions has been identified in Juniper Networks Junos OS. This issue affects systems running Junos OS on Linux-based line cards, including various models such as MPC7, MPC8, MPC9, MPC10, MPC11, and several others. The vulnerability allows a privileged local attacker to gain root access on the affected line cards. This access is achieved by executing a script as root during the boot-up process of the line card, without the need for a root password. The vulnerability is present in all versions of Junos OS prior to 22.4R3-S8, as well as specific ranges in versions 23.x, 24.x, and 25.2.
Users can upgrade to Junos OS versions 22.4R3-S8, 23.2R2-S6, 23.4R2-S6, 24.2R2-S3, 24.4R2, 25.2R2, 25.4R1, or any subsequent release to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/orangecertcc/security-research/security/advisories/GHSA-fwhc-gh5m-v8fq | [email protected] | Third Party Advisory |
| https://kb.juniper.net/JSA107863 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | <= 22.4 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 22.4 r3-s7 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
| juniper ex9200 | All versions |
CPE
Remediation
| |
| juniper fpc3-ptx-u2 | All versions |
CPE
Remediation
| |
| juniper fpc3-ptx-u3 | All versions |
CPE
Remediation
| |
| juniper fpc3-sff-ptx | All versions |
CPE
Remediation
| |
| juniper lc1101 | All versions |
CPE
Remediation
| |
| juniper lc1102 | All versions |
CPE
Remediation
| |
| juniper lc1104 | All versions |
CPE
Remediation
| |
| juniper lc1105 | All versions |
CPE
Remediation
| |
| juniper lc2101 | All versions |
CPE
Remediation
| |
| juniper lc2103 | All versions |
CPE
Remediation
| |
| juniper lc480 | All versions |
CPE
Remediation
| |
| juniper lc4800 | All versions |
CPE
Remediation
| |
| juniper lc9600 | All versions |
CPE
Remediation
| |
| juniper mpc10 | All versions |
CPE
Remediation
| |
| juniper mpc11 | All versions |
CPE
Remediation
| |
| juniper mpc7e-10g | All versions |
CPE
Remediation
| |
| juniper mpc8e | All versions |
CPE
Remediation
| |
| juniper mpc9e | All versions |
CPE
Remediation
| |
| juniper mx-spc3 | All versions |
CPE
Remediation
| |
| juniper mx304 | All versions |
CPE
Remediation
| |
| juniper srx5k-spc3 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Apr 9, 2026 | CVE Modified | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |